information about the syntax for the router, use the question mark ( Figure 1 uses an example of the output from the show ip cache verbose flow to show how to associate the headings with the correct data fields when there are two or more lines of headings and two or more lines of data fields. Flows •In order for the BGP information to be populated in the main cache you must either have a NetFlow export destination configured or NetFlow aggregation configured. Assigning another NetFlow input filter sampler to a class overwrites the previous one. After NetFlow is configured on Router B, you can display all NetFlow statistics for the server by entering the show ip cache flow command or the show ip cache verbose flow command for Router B. Range of number of packets in the flows to be matched. Specify the export Displays the configured protocol-creation filters. Using the show ip flow top-talkers command to display the aggregated statistics from the flows on a router for the highest volume applications and protocols in your network helps you identify, and classify, security problems such as a denial of service (DoS) attacks because DoS attack traffic almost always show up as one of the highest volume protocols in your network when a DoS attack is in progress. all Includes Name of For the value. If you do not specify match criteria and there are flows in the cache that include the field that you used to aggregate the flows on, all of the flows will match. Range is from 1 through 604800. NetFlow accounting with input filter sampling cannot be run concurrently with (ingress) NetFlow accounting, egress NetFlow accounting, or random sampled NetFlow on the same interface, or subinterface. the export timeout value for the sampler table. The ing_lnks field indicates that the Netflow is configured in ingress direction for a particular interface corresponding to the NP. timeout configured for this cache, in seconds. according to the specified sorting criteria. Version 8.2(2) and later releases provide a more robust NetFlow implementation. destination-tos keyword was added to support The following is a sample display of an autonomous system aggregation cache with the show ip cache flow aggregation as command: The following is a sample display of an autonomous system aggregation cache for the prefix mask 10.0.0.0 255.0.0.0 with the show ip cache flow aggregation as command: The following is a sample display of an destination prefix TOS cache with the show ip cache flow aggregation destination-prefix-tos command: The following is a sample display of an prefix port aggregation cache with the show ip cache flow aggregation prefix-port command: The following is a sample display of an prefix port aggregation cache for the prefix mask 172.16.0.0 255.255.0.0 with the show ip cache 172.16.0.0 255.255.0.0 flow aggregation prefix-port command: The following is a sample display of an protocol port aggregation cache with the show ip cache flow aggregation protocol-port command: Table 10 describes the significant fields shown in the output of the show ip cache flow aggregation command. This command was integrated into Cisco IOS Release 12.3(6). interface table. Table 15 show ip cache verbose flow Field Descriptions in NetFlow BGP Next-Hop Accounting Output. For Release 12.2(17a)SX and later releases, use the show mls netflow ip sw-installed command. To specify a null flow mask, use the no form of this command. packets that the producer could not enqueue to the NetFlow server due to errors Possible sorting options are: Enter Testing the configuration. •08 indicates an IP version 6 (IPv6) flow. (Optional) Displays the entries that are downloaded on the specified module; see the "Usage Guidelines" section for valid values.